Re: [SECURITY] [DSA 729-1] New PHP4 packages fix denial of service

From: John GALLET (john.gallet_at_wanadoo.fr)
Date: 05/27/05

  • Next message: ACROS Security: "RE: ACROS Security: HTML Injection in BEA WebLogic Server Console (2)"
    Date: Fri, 27 May 2005 10:24:43 +0200 (CEST)
    To: bugtraq@securityfocus.com
    
    

    Hi there,

    > An iDEFENSE researcher discovered two problems in the image processing
    > functions of PHP, a server-side, HTML-embedded scripting language, of
    > which one is present in woody as well. When reading a JPEG image, PHP
    > can be tricked into an endless loop due to insufficient input
    > validation.

    I don't see anything in the latest change logs, could anyone please point
    me to more information about this error ? Is it located in the GD php
    extension ?

    Sincerely,
    JG


  • Next message: ACROS Security: "RE: ACROS Security: HTML Injection in BEA WebLogic Server Console (2)"

    Relevant Pages

    • Re: Upload and resize file
      ... That one is weird and not simple PHP code, which will do your task easily. ... print "Please upload only a JPEG image with the extension .jpg or ... decompress jpeg image to pnm file ...
      (php.general)
    • Re: [PHP] Re: Upload and resize file
      ... simple PHP code, which will do your task easily. ... print "Please upload only a JPEG image with the extension .jpg ...
      (php.general)
    • Re: [PHP] Upload and resize file
      ... print "Please upload only a JPEG image with the extension .jpg or ... decompress jpeg image to pnm file ...
      (php.general)
    • RE: [PHP] Re: Upload and resize file
      ... Subject: [PHP] Re: Upload and resize file ... decompress jpeg image to pnm file (a raw ...
      (php.general)
    • PHP Interbase or Firebird database JPEG output
      ... I am using the PHP 4.3.4 with a standard php.ini file. ... I am tryong to output a blob field that contains a jpeg image using ... output of three fields o text from the database. ... What HTML or php functions should I specify to output this ...
      (comp.lang.php)